US2025014021A1PendingUtilityA1

Cryptographic mechanisms including means for verifying the identity of a user of a system utilising key distribution involving additional devices

Assignee: ENTERSEKT INTERNATIONAL LTDPriority: Nov 1, 2016Filed: Sep 24, 2024Published: Jan 9, 2025
Est. expiryNov 1, 2036(~10.3 yrs left)· nominal 20-yr term from priority
H04L 63/0876H04L 63/0853G06Q 20/3278G06Q 20/3263G07F 7/10G06Q 20/4014G06Q 40/00G06Q 30/06G06Q 20/3821
67
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Cryptographic mechanisms including means for verifying the identity of a user of a system utilising key distribution involving additional devices are provided, including a system and a method for verifying an association between a communication device and a user. In a method conducted at a remote server, a token including a cryptogram obtained from a proximity communication enabled smart card is received from a communication device via a secure communication channel by way of which the communication device is uniquely identifiable by the remote server. The proximity communication enabled smart card having generated the cryptogram by signing a set of data elements using a cryptographic key stored within the proximity communication enabled smart card and having previously been associated with the user in the user account. The received token is validated and, if valid, a device identifier is stored as a verified device identifier.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method for verifying the identity of a user of a system utilising key distribution involving additional devices including verifying an association between a communication device and a user to enroll an application executing on the communication device through which the user interacts against a user account maintained by an entity, the method conducted at a remote server maintained on behalf of the entity comprising:
 establishing a secure communication channel between the remote server and the communication device with the communication device uniquely identifiable by the remote server over the secure communication channel;   receiving, at the remote server from the communication device, a device identifier and a user identifier for association with each other, the user identifier having previously been associated with the user account and using the user identifier to identify the user account associated therewith;   receiving a token at the remote server from the communication device via the secure communication channel, the token having been obtained by the communication device from a proximity communication enabled smart card of the user via a proximity communication interface, the token including a cryptogram and the proximity communication enabled smart card having generated the cryptogram by signing a set of data elements using a cryptographic key stored within the proximity communication enabled smart card, the cryptographic key having previously been securely generated for an issuer of the proximity communication enabled smart card and previously associated with the user in the user account, such that data elements signed using the cryptographic key can be validated by an authorisation system associated with the issuer of the proximity communication enabled smart card;   validating the received token at the remote server, including verifying the legitimacy of the cryptogram based on information known to the remote server; and,   once determined that the token is valid, storing, at the remote server, the device identifier as a verified device identifier in association with one or both of the user identifier and the user account, wherein, once enrolled, the communication device and the application executing thereon are usable to interact with the entity remotely, via a communication network.   
     
     
         2 . The method as claimed in  claim 1 , wherein the device identifier is a device certificate having an associated public-private key pair. 
     
     
         3 . The method as claimed in  claim 2 , wherein the proximity communication enabled smart card is issued to the user by the entity for personal use such that the user is associated with the proximity communication enabled smart card, and wherein the cryptographic key is unique to the proximity communication enabled smart card. 
     
     
         4 . The method as claimed in  claim 3 , wherein an account database stores a master key that was used to generate the cryptographic key, and wherein legitimacy of the cryptogram is verifiable by the entity having issued the proximity communication enabled smart card. 
     
     
         5 . The method as claimed in  claim 4 , including transmitting the set of data elements to the communication device. 
     
     
         6 . The method as claimed in  claim 5 , wherein the method conducted at the communication device includes:
 receiving the set of data elements from the remote server;   transmitting the set of data elements to the proximity communication enabled smart card via the proximity communication interface; and,   receiving the token from the proximity communication enabled smart card via the proximity communication interface.   
     
     
         7 . The method as claimed in  claim 6 , wherein the set of data elements are included in a command requesting the proximity communication enabled smart card to generate the token for a transaction, wherein the command is a Card Action Analysis command. 
     
     
         8 . The method as claimed in  claim 7 , wherein the method conducted at the proximity communication enabled smart card includes:
 receiving the set of data elements from the communication device;   generating the token including the cryptogram by signing the set of data elements using the cryptographic key; and,   transmitting the token to the communication device via the proximity communication interface.   
     
     
         9 . The method as claimed in  claim 8 , wherein the token is in the form of the resulting cipher text produced by signing the of set data elements using the cryptographic key. 
     
     
         10 . The method as claimed in  claim 9 , wherein establishing the secure communication channel between the remote server and the communication device includes encrypting messages or payloads transmitted to the communication device with a public key corresponding to a private-public key pair of the communication device. 
     
     
         11 . The method as claimed in  claim 10 , wherein encrypting messages or payloads transmitted to the communication device includes encrypting messages or payloads with a private key corresponding to a unique private-public key pair of the remote server. 
     
     
         12 . The method as claimed in  claim 1 , wherein storing the device identifier includes combining the device identifier with the token. 
     
     
         13 . The method as claimed in  claim 1 , including creating, by the remote server in an enrolment database, a user record associated with the user account and storing the device identifier in the user record. 
     
     
         14 . The method as claimed in  claim 6 , wherein transmitting the data elements to and receiving the token from the proximity communication enabled smart card includes interacting with the proximity communication enabled smart card via the proximity communication interface. 
     
     
         15 . The method as claimed in  claim 1 , wherein the proximity communication interface is a radio frequency proximity communication interface. 
     
     
         16 . A system for verifying the identity of a user of a system utilising key distribution involving additional devices including verifying an association between a communication device and a user to enroll an application executing on the communication device through which the user interacts against a user account maintained by an entity, the system including a remote server comprising a non-transitory computer-readable storage medium; and one or more processors coupled to the non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium comprises program instructions that, when executed on the one or more processors, cause the remote server to perform operations comprising:
 establishing a secure communication channel between the remote server and the communication device with the communication device uniquely identifiable by the remote server over the secure communication channel;   receiving, at the remote server from the communication device, a device identifier and a user identifier for association with each other, the user identifier having previously been associated with the user account and using the user identifier to identify the user account associated therewith;   receiving a token at the remote server from the communication device via the secure communication channel, the token having been obtained by the communication device from a proximity communication enabled smart card of the user via a proximity communication interface, the token including a cryptogram and the proximity communication enabled smart card having generated the cryptogram by signing a set of data elements using a cryptographic key stored within the proximity communication enabled smart card, the cryptographic key having previously been securely generated for an issuer of the proximity communication enabled smart card and previously associated with the user in the user account, such that data elements signed using the cryptographic key can be validated by an authorisation system associated with the issuer of the proximity communication enabled smart card;   validating the received token at the remote server, including verifying the legitimacy of the cryptogram based on information known to the remote server; and,   once determined that the token is valid, storing, at the remote server, the device identifier as a verified device identifier in association with one or both of the user identifier and the user account, wherein, once enrolled, the communication device and the application executing thereon are usable to interact with the entity remotely, via a communication network.   
     
     
         17 . The system as claimed in  claim 16 , including the communication device comprising a non-transitory computer-readable storage medium; and one or more processors coupled to the non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium comprises program instructions that, when executed on the one or more processors, cause the communication device to perform operations comprising:
 obtaining the device identifier capable of uniquely identifying the communication device;   receiving the user identifier input into the communication device via a user interface, the user identifier having previously been associated with the user account;   establishing the secure communication channel between the remote server and the communication device with the communication device uniquely identifiable by the remote server over the secure communication channel;   transmitting the device identifier and user identifier to the remote server for association with each other thereat;   obtaining, via the proximity communication interface, the token including the cryptogram from the proximity communication enabled smart card of the user which generates the cryptogram by signing the set of data elements using the cryptographic key stored within the proximity communication enabled smart card; and,   transmitting the token to the remote server via the secure communication channel by way of which the communication device is uniquely identifiable by the remote server.   
     
     
         18 . The system as claimed in  claim 17 , including the proximity communication enabled smart card comprising a non-transitory computer-readable storage medium; and one or more processors coupled to the non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium comprises program instructions that, when executed on the one or more processors, cause the proximity communication enabled smart card to perform operations comprising:
 generating the token including the cryptogram by signing the set of data elements using the cryptographic key; and,   transmitting the token to the communication device via the proximity communication interface.   
     
     
         19 . A computer program product for verifying the identity of a user of a system utilising key distribution involving additional devices including verifying an association between a communication device and a user to enroll an application executing on the communication device through which the user interacts against a user account maintained by an entity, the computer program product comprising a non-transitory computer-readable medium having stored computer-readable program code for performing the steps of:
 establishing a secure communication channel between the remote server and the communication device with the communication device uniquely identifiable by the remote server over the secure communication channel;   receiving, at the remote server from the communication device, a device identifier and a user identifier for association with each other, the user identifier having previously been associated with the user account and using the user identifier to identify the user account associated therewith;   receiving a token at the remote server from the communication device via the secure communication channel, the token having been obtained by the communication device from a proximity communication enabled smart card of the user via a proximity communication interface, the token including a cryptogram and the proximity communication enabled smart card having generated the cryptogram by signing a set of data elements using a cryptographic key stored within the proximity communication enabled smart card, the cryptographic key having previously been securely generated for an issuer of the proximity communication enabled smart card and previously associated with the user in the user account, such that data elements signed using the cryptographic key can be validated by an authorisation system associated with the issuer of the proximity communication enabled smart card;   validating the received token at the remote server, including verifying the legitimacy of the cryptogram based on information known to the remote server; and,   once determined that the token is valid, storing, at the remote server, the device identifier as a verified device identifier in association with one or both of the user identifier and the user account, wherein, once enrolled, the communication device and the application executing thereon are usable to interact with the entity remotely, via a communication network.

Join the waitlist — get patent alerts

Track US2025014021A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.